
CampaignPress Security & Risk Analysis
wordpress.org/plugins/campaignpressDo you send a newsletter based on content from your website using your Mailchimp account? Ever want to select a bunch of posts and have them appear in …
Is CampaignPress Safe to Use in 2026?
Generally Safe
Score 85/100CampaignPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Campaignpress v1.4 exhibits a generally strong security posture, with no known historical vulnerabilities and a robust approach to handling sensitive operations. The static analysis reveals a significant number of REST API routes, all of which correctly implement permission callbacks, minimizing the risk of unauthorized access through this common entry point. The plugin also shows good practice in its SQL query handling, with a high percentage of prepared statements, and a commendable rate of output escaping. The absence of file operations, external HTTP requests, and dangerous functions further contributes to its secure design.
However, there are specific areas for improvement. The most notable concern is the complete absence of nonce checks across all identified entry points, including the 23 REST API routes. While permission checks are in place, nonce validation is a crucial defense against Cross-Site Request Forgery (CSRF) attacks. Furthermore, a single taint flow was identified with unsanitized paths. Although classified as non-critical, this warrants attention as it represents a potential pathway for malicious input to be processed without proper sanitization.
In conclusion, Campaignpress v1.4 is well-designed in many respects, particularly in its handling of database queries and output. The lack of historical vulnerabilities is a positive indicator of its maintainers' commitment to security. The primary weaknesses lie in the omission of nonce checks and the presence of a single unsanitized taint flow, which, while not leading to immediate critical vulnerabilities based on the provided data, represent potential risks that should be addressed to further enhance the plugin's overall security.
Key Concerns
- Missing nonce checks on entry points
- Flow with unsanitized paths
CampaignPress Security Vulnerabilities
CampaignPress Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
CampaignPress Attack Surface
REST API Routes 23
WordPress Hooks 15
Maintenance & Trust
CampaignPress Maintenance & Trust
Maintenance Signals
Community Trust
CampaignPress Alternatives
Featured Images in RSS for Mailchimp & More
featured-images-for-rss-feeds
Send images to RSS instantly for free. Output blog or WooCommerce photos to Mailchimp RSS email campaigns, ActiveCampaign, Hubspot, Feedly and more.
Newspack Newsletters
newspack-newsletters
Create email newsletters with the block editor and distribute them with your favorite ESP mailing lists.
Subscriber Discounts for WooCommerce
subscriber-discounts-for-woocommerce
Easily send mailing list subscribers a discount code for joining your list.
Campaign Archive Block for Mailchimp
campaign-archive-block-for-mailchimp
Adds a block to show an archive for Mailchimp campaigns.
ChimpBridge – Create and Send Mailchimp Campaigns in WordPress
chimpbridge
Create and send Mailchimp Campaigns right inside of the WordPress admin.
CampaignPress Developer Profile
3 plugins · 700 total installs
How We Detect CampaignPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/campaignpress/../../dist/css/tailwind.css/wp-content/plugins/campaignpress/../../js/dist/app.css/wp-content/plugins/campaignpress/../../js/dist/app.js/wp-content/plugins/campaignpress/../../js/dist/app.js/../../dist/css/tailwind.css?ver=/../../js/dist/app.css?ver=/../../js/dist/app.js?ver=HTML / DOM Fingerprints
campaignpress-ui-container--- Action: pluginInit ------ Action: addMenuItem ------ Action: pageHtml ------ Action: adminPluginAssets ---+1 moredata-pagedata-noncedata-show-debugorchestrated_campaignpress_app/wp-json/orchestrated_campaignpress/v1/